300-220 CBRTHD: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ21
Threat Hunting Processes
The SOC team receives an alert for a user sign-in from an unusual country. After reviewing the SIEM logs, the team confirms that the user never signed in from that country. The incident is reported to the IT administrator, who resets the user’s password.
Which threat-hunting phase was used initially?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion